Marshall Bowers c84da37030 rpc: Add support for OAEP-based encryption format (#15058)
This PR adds support for a new encryption format for exchanging access
tokens during the authentication flow.

The new format uses Optimal Asymmetric Encryption Padding (OAEP) instead
of PKCS#1 v1.5, which is known to be vulnerable to side-channel attacks.

**Note: We are not yet encrypting access tokens using the new format, as
this is a breaking change between the client and the server. This PR
only adds support for it, and makes it so the client and server can
decrypt either format moving forward.**

This required bumping the RSA key size from 1024 bits to 2048 bits. This
is necessary to be able to encode the access token into the ciphertext
when using OAEP.

This also follows OWASP recommendations:

> If ECC is not available and RSA must be used, then ensure that the key
is at least 2048 bits.
>
> —
[source](https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms)

Release Notes:

- N/A
2024-07-23 21:25:25 -04:00
2024-06-14 16:15:13 -06:00
2024-05-15 11:06:05 -06:00
2024-07-05 22:00:18 -04:00
2024-07-23 14:21:56 -06:00
2024-07-09 16:27:55 -04:00
2024-07-09 09:21:42 +02:00
2024-07-01 19:04:58 -04:00
2024-07-23 20:11:48 -04:00
2024-06-25 10:58:11 -04:00
WIP
2023-12-14 09:25:14 -07:00
2024-07-09 09:21:42 +02:00
2024-07-09 09:21:42 +02:00
2024-04-15 14:00:56 -06:00
2024-07-09 14:05:29 -07:00
2024-07-09 09:21:42 +02:00

Zed

CI

Welcome to Zed, a high-performance, multiplayer code editor from the creators of Atom and Tree-sitter.


Installation

Packaging status

On macOS and Linux you can download Zed directly or install Zed via your local package manager.

Other platforms are not yet available:

Developing Zed

Contributing

See CONTRIBUTING.md for ways you can contribute to Zed.

Also... we're hiring! Check out our jobs page for open roles.

Licensing

License information for third party dependencies must be correctly provided for CI to pass.

We use cargo-about to automatically comply with open source licenses. If CI is failing, check the following:

  • Is it showing a no license specified error for a crate you've created? If so, add publish = false under [package] in your crate's Cargo.toml.
  • Is the error failed to satisfy license requirements for a dependency? If so, first determine what license the project has and whether this system is sufficient to comply with this license's requirements. If you're unsure, ask a lawyer. Once you've verified that this system is acceptable add the license's SPDX identifier to the accepted array in script/licenses/zed-licenses.toml.
  • Is cargo-about unable to find the license for a dependency? If so, add a clarification field at the end of script/licenses/zed-licenses.toml, as specified in the cargo-about book.
S
Description
GPUI – Community Edition maintained by Oak Team
https://gpui-ce.github.io/
Readme
257 MiB
Languages
Rust 95.5%
WGSL 1.2%
Metal 1.1%
HLSL 1.1%
Python 0.7%
Other 0.3%